DEV Community

Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com on

Should You Change Your Email After a Data Breach?

Your email turned up in a breach, and your first instinct is to throw the address away and start over. I understand the instinct. I run AliasFleet, an email-alias service, and the whole point of the product is making one leaked address easy to kill without touching anything else in your life. Even so, here is my honest answer: do not change your email address.

Have I Been Pwned is where most people check, and its creator has been asked your exact question. Troy Hunt's answer: "Frankly, if you've got strong, unique passwords, I wouldn't do anything." The man runs the canonical breach database. His answer is no, with one condition attached. The condition is the whole article.

The official advice never mentions a new address

What does the FTC say to do after a data breach?

Change your passwords, turn on multifactor authentication, and check what was actually exposed at IdentityTheft.gov. That is the FTC's advice in full. Read it twice and notice what is missing: changing your email address appears nowhere.

The IdentityTheft.gov breach page goes further. It walks through every data type a breach can expose: social security number, login and password, card numbers, bank accounts, driving licence, passport, medical cover. Each one gets its own recovery steps. None of them is "get a new email address." The one adjacent line is the advice to change your username where possible, which is not the same as changing the address you are reachable at, and does not kill the leaked identity either. And the page makes a point that applies perfectly to email even though it is written about social security numbers: a new number, it says, likely will not solve all your problems, because agencies and other entities will still have records linking you to your old number. Swap "number" for "address" and you have the entire argument against changing your email.

The FTC also has a word for the notices people are tempted to ignore: the old gaming account, the dorky username from years ago. The warning is that the password on that forgotten account is probably the password on your bank account too. Same pair, bigger target. Which is exactly why the advice starts with passwords and never mentions the address.

The old address does not die when you leave

If I change my address, is the old one gone?

No. The address in the stolen database stays exactly where it is, and every copy of that dump keeps working. Breach data gets re-traded and folded into bigger combo lists. Nobody knows how long a given dump keeps circulating, but old addresses keep turning up in new spam runs.

Even your email provider agrees, in a sense. Google spent more than twenty years refusing to let anyone change a Gmail address. When it finally allowed it in 2026, the old address did not die. It becomes an alternate address on the same account: mail sent to both the old and the new address lands in the same inbox. You get three changes in a lifetime, one per year. Changing your address, in Google's implementation, means adding an address. It is not an escape.

What does the move actually cost?

You are not changing a username. You are changing the key to every lock you own, and every lock gets changed by hand. Every password reset in your life flows through that address. Every account you have opened in the last decade has it on file, and so does every person who knows how to reach you.

A new address means updating all of them, one by one, and every account you forget becomes a door you can no longer unlock. When the move is done, you have two inboxes to check for the rest of your life, because the old address is still the recovery address on half the accounts you missed. The cost is not money. It is a lost afternoon spent on a change that does not fix anything.

Then there is the work nobody prices in: the bank, the shops, the airline, the school portal, the dentist, the two-factor codes for half your accounts, the mailing lists you actually want to keep. Each one is a login, a settings page, a verification email, a wait. And while you are doing all of it, the old address is still in the dump, still receiving the phishing, still the username on every account you forgot to update.

What actually fixes a breached address

The full ordered version of this lives in our breach-response guide. Here is the short version, in the order the official guidance gives it.

Which passwords do I change first?

The breached site's, then every other site where you used the same one, because the leaked password is the weapon here, not the leaked address. Attackers feed leaked email and password pairs into software that tries them on site after site, automatically, while they sleep.

This is called credential stuffing, and it works for one reason: people reuse passwords. The FTC's case against the alcohol delivery platform Drizly is the textbook example. An executive's seven-character password, made public in an unrelated breach, was all a hacker needed to get into Drizly's database of 2.5 million users. Read that again: not a zero-day, a reused password.

Start with your email account, because every reset flows through it, and give it a unique password plus a second factor. Then the bank. The real work is finding every account where that password lived. A password manager turns that from a lost weekend into an afternoon.

What is the single highest-value step after that?

Multifactor authentication. CISA's director put a number on it: MFA makes you 99 percent less likely to get hacked, because even if the attacker holds your password, they still cannot clear the second check. Turn it on for your email first, then your bank, then everything important.

What about the phishing that follows?

Expect it, and do not engage. After a breach, scammers pose as the breached company and send follow-ups quoting your real data back at you. The FTC's standing warning is the same every time: do not hand over personal information unless you started the contact. Treat every link in breach-related mail as suspect and navigate to the site yourself.

If the dump included ID numbers or bank details, the IdentityTheft.gov steps for fraud alerts and credit freezes apply, and that is the one case where this stops being an email problem.

When a fresh address is the right call

Two cases. Both honest, both with caveats attached.

Is there any case where I should change it?

Yes. If the address itself has become the weapon, the maths changes. Targeted harassment, doxxing, someone using the address to find you or flood you: the address is not just leaked, it is aimed. A fresh, unlisted address for the important accounts is warranted.

This is no longer about the dump. It is about removing a handle people are actively using to reach you.

The second case is the credential-stuffing one. If you reused the same password across half the internet and you cannot be sure you caught every account, a new address on your critical accounts buys distance. Credential stuffing needs the username half of the pair too, and a fresh address removes that half.

Now the caveats, because these matter. Keep the old address alive somewhere you check, because password resets and account notices still flow to it, and because any account you forgot now answers to the old address. Keep the new address quiet. Tell almost nobody. And be honest with yourself about what you bought: a new email without MFA is a new coat of paint on a door with a broken lock. Change the passwords, turn on the second factor, and let the new address be the third step, not the first.

Make sure you never have to ask this again

How do aliases make this question obsolete?

Give every website its own email alias. The next breach leaks an address that belongs to one site only, and when the spam or the phishing starts arriving on it, you pause that one alias and nothing else in your life changes. Your real address never enters the next stolen database, because it never entered any of them.

Here is the limitation I will not skip. Aliases do not fix the address you have already handed out for a decade. Nothing does. No product reaches back in time and scrubs your address from old dumps. What aliases do is stop the list growing, which is the part you still control.

The free tier covers 10 active aliases, which is enough for the accounts that matter most while you build the habit: banking, shopping, social, news. The set-up guide takes about two minutes, the use-cases guide tells you where to point them first, and the leak-tracing piece explains the mechanism. Start with the sites that have already burned you once. If you have never used one, this is what an alias is, and the docs cover the forwarding mechanics behind it.

Keep the address. Change what it can do.

Top comments (0)